Remove Active Directory forest from AADC

%3CLINGO-SUB%20id%3D%22lingo-sub-2104114%22%20slang%3D%22en-US%22%3ERemove%20Active%20Directory%20forest%20from%20AADC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2104114%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20have%20a%20single%20instance%20of%20AADC%20setup%20that%20is%20syncing%20two%20separate%20AD%20forests%20into%20single%20tenant.%3C%2FP%3E%3CP%3EI%20would%20like%20to%20remove%20one%20of%20the%20forests%20from%20AADC%2C%20but%20I%20do%20not%20want%20the%20cloud%20users%20to%20be%20deleted.%20I%20would%20like%20them%20to%20be%20converted%20to%20cloud%20users.%3C%2FP%3E%3CP%3EIs%20there%20a%20process%20for%20this%3F%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2104114%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAuthentication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2147421%22%20slang%3D%22en-US%22%3ERe%3A%20Remove%20Active%20Directory%20forest%20from%20AADC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2147421%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F138356%22%20target%3D%22_blank%22%3E%40Jason%20Gaffney%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAFAIK%20there%20is%20no%20way%20to%20prevent%20the%20(temporary)%20deletion%20of%20the%20synced%20objects%20when%20removing%20an%20AD%20forest%20from%20AAD%20Connect%20configuration.%3C%2FP%3E%3CP%3EYou%20can%2C%20immediately%20after%20the%20removal%2C%20go%20into%20deleted%20users%20and%20restore%20them.%20At%20that%20point%20they%20will%20become%20cloud%20users%20and%20retain%20all%20their%20data%2C%20licenses%2C%20etc..%3C%2FP%3E%3CP%3EYou%20might%20also%20want%20to%20check%20the%20deleted%20groups%20section%20for%20any%20groups%20that%20were%20affected%20by%20the%20AD%20forest%20removal.%3C%2FP%3E%3CP%3EAlso%20AAD%20Connect%20has%20a%20deletion%20threshold%20to%20prevent%20accidental%20mass%20deletions.%20This%20is%20set%20by%20default%20at%20500.%3C%2FP%3E%3CP%3ETo%20remove%20this%20run%20Disable-ADSyncExportDeletionThreshold%3C%2FP%3E%3CP%3EAfter%20you're%20done%2C%20set%20it%20again%20via%26nbsp%3B%3CSPAN%3EEnable-ADSyncExportDeletionThreshold%20-DeletionThreshold%20500%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello,

I have a single instance of AADC setup that is syncing two separate AD forests into single tenant.

I would like to remove one of the forests from AADC, but I do not want the cloud users to be deleted. I would like them to be converted to cloud users.

Is there a process for this?

Thank you

2 Replies

Hi @Jason Gaffney 

AFAIK there is no way to prevent the (temporary) deletion of the synced objects when removing an AD forest from AAD Connect configuration.

You can, immediately after the removal, go into deleted users and restore them. At that point they will become cloud users and retain all their data, licenses, etc..

You might also want to check the deleted groups section for any groups that were affected by the AD forest removal.

Also AAD Connect has a deletion threshold to prevent accidental mass deletions. This is set by default at 500.

To remove this run Disable-ADSyncExportDeletionThreshold

After you're done, set it again via Enable-ADSyncExportDeletionThreshold -DeletionThreshold 500

@Steve Hernou 

 

 

Right, but deletion needs to be avoided as you have to reset passwords upon restoring, that's not a viable solution.

 

I have found that I was able to accomplish this by disabling ADsync in the tenant. This will convert all accounts to cloud accounts and retains passwords.

Then a clean AADC install on a new machine and soft match the needed accounts.

All accounts and password stay in tact without anything being deleted :)